tuwunel_service/federation/scheme.rs
1//! Adapters that build the `Input` for ruma's [`AuthScheme`] and
2//! [`PathBuilder`] traits from tuwunel's federation context.
3//!
4//! Federation endpoints span several auth/path-builder combinations
5//! (`ServerSignatures` + `VersionHistory`, `ServerSignatures` + `SinglePath`,
6//! and a handful of `NoAuthentication`/`NoAccessToken` variants). The
7//! generic-associated-type `Input<'a>` of each ruma trait varies per impl, so
8//! a single bound on `OutgoingRequest` cannot supply the right value uniformly.
9//! [`FedAuth`] and [`FedPath`] each accept tuwunel's federation context and
10//! return the appropriate `Input` for the concrete auth scheme or path builder
11//! at the call site.
12
13use std::borrow::Cow;
14
15use ruma::{
16 OwnedServerName,
17 api::{
18 SupportedVersions,
19 auth_scheme::{AuthScheme, NoAccessToken, NoAuthentication, SendAccessToken},
20 federation::authentication::{ServerSignatures, ServerSignaturesInput},
21 path_builder::{PathBuilder, SinglePath, VersionHistory},
22 },
23 signatures::Ed25519KeyPair,
24};
25
26/// Builds ruma authentication input from the local federation identity.
27///
28/// Implementations bridge each concrete [`AuthScheme`] to the common origin,
29/// destination, and signing-key context available to the service.
30pub trait FedAuth: AuthScheme {
31 /// Constructs the authentication input expected by this scheme.
32 ///
33 /// Schemes that do not authenticate ignore some or all supplied context.
34 fn input(
35 origin: OwnedServerName,
36 dest: OwnedServerName,
37 keypair: &Ed25519KeyPair,
38 ) -> <Self as AuthScheme>::Input<'_>;
39}
40
41impl FedAuth for NoAuthentication {
42 fn input(_: OwnedServerName, _: OwnedServerName, _: &Ed25519KeyPair) {}
43}
44
45impl FedAuth for NoAccessToken {
46 fn input(_: OwnedServerName, _: OwnedServerName, _: &Ed25519KeyPair) -> SendAccessToken<'_> {
47 SendAccessToken::None
48 }
49}
50
51impl FedAuth for ServerSignatures {
52 fn input(
53 origin: OwnedServerName,
54 dest: OwnedServerName,
55 keypair: &Ed25519KeyPair,
56 ) -> ServerSignaturesInput<'_> {
57 ServerSignaturesInput::new(origin, dest, keypair)
58 }
59}
60
61/// Builds ruma path input from the remote server's supported versions.
62///
63/// Implementations adapt either a single fixed path or a versioned endpoint
64/// history to the same federation request path.
65pub trait FedPath: PathBuilder {
66 /// Constructs the path-builder input expected by this endpoint.
67 ///
68 /// Single-path endpoints ignore the advertised version history.
69 fn input(supported: &SupportedVersions) -> <Self as PathBuilder>::Input<'_>;
70}
71
72impl FedPath for SinglePath {
73 fn input(_: &SupportedVersions) {}
74}
75
76impl FedPath for VersionHistory {
77 fn input(supported: &SupportedVersions) -> Cow<'_, SupportedVersions> {
78 Cow::Borrowed(supported)
79 }
80}